Restricted access to root DSA (Giant Tortoise)

/DD.NTADDR=Anne_Philpott#l#a#r#HWC/G=Anne/S=Philpott/@lotus.hc-sc.x400.gc.ca Tue, 25 April 1995 18:35 UTC

Received: from ietf.nri.reston.va.us by IETF.CNRI.Reston.VA.US id aa08483; 25 Apr 95 14:35 EDT
Received: from CNRI.Reston.VA.US by IETF.CNRI.Reston.VA.US id aa08479; 25 Apr 95 14:35 EDT
Received: from haig.cs.ucl.ac.uk by CNRI.Reston.VA.US id aa17257; 25 Apr 95 14:35 EDT
Received: from bells.cs.ucl.ac.uk by haig.cs.ucl.ac.uk with local SMTP id <g.05507-0@haig.cs.ucl.ac.uk>; Tue, 25 Apr 1995 18:11:51 +0100
Received: from gatepas.gc.ca by bells.cs.ucl.ac.uk with Internet SMTP id <g.20768-0@bells.cs.ucl.ac.uk>; Tue, 25 Apr 1995 18:11:19 +0100
Sender: ietf-archive-request@IETF.CNRI.Reston.VA.US
From: /DD.NTADDR=Anne_Philpott#l#a#r#HWC/G=Anne/S=Philpott/@lotus.hc-sc.x400.gc.ca
Reply-To: /DD.NTADDR=Anne_Philpott#l#a#r#HWC/G=Anne/S=Philpott/@lotus.hc-sc.x400.gc.ca
Errors-To: /DD.NTADDR=Anne_Philpott#l#a#r#HWC/G=Anne/S=Philpott/O=lotus/PRMD=gc+hc.sc/ADMD=govmt.canada/C=ca/@x400.gc.ca
Date: Tue, 25 Apr 1995 13:10:52 -0400
Priority: normal
Content-Identifier: Restricted acces
X400-Content-Type: P2-1984
X400-MTS-Identifier: [/PRMD=gc+hc.sc/ADMD=govmt.canada/C=ca/; XGW-950425131052-0400-03264]
To: managers@nameflow.dante.net
Cc: osi-ds@cs.ucl.ac.uk, quipu@cs.ucl.ac.uk
Subject: Restricted access to root DSA (Giant Tortoise)
Message-Id: <"0425171052-Restricted access to root DSA (Giant Tortoise)"*/DD.NTADDR=Anne_Philpott#l#a#r#HWC/G=Anne/S=Philpott/O=lotus/PRMD=gc+hc.sc/ADMD=govmt.canada/C=ca/@MHS>
Importance: normal

Dear directory managers,

Apologies for cross posting, but this is an important message for 
Directory
managers.

In order to phase out the Root-of-the-world DSA (the "Giant Tortoise") 
we
announced in a previous message that access would be limited. An
undocumented feature of Quipu allows us to further tighten the
restrictions.

The coming changes may effect a large part of the Directory starting 
from
the 2nd of May 1995. We will be testing restricted access for the DSA
"Giant Tortoise" from the 2 May until the 14 May 1995. As from 15 May 
1995
access restrictions to the Giant Tortoise will be a fact. The access
restrictions will have as minimal influence on the operational service 
as
possible.

The rest of this message will respectively explain what will change for
directory users and what will change for Directory System Agents 
(DSAs).

What will change for directory _USERS_?
In principle directory users are NOT allowed to connect to the Giant
Tortoise anymore as they should contact their local DSA.
The following users will be allowed to connect to the Giant Tortoise:
* the managers of the Giant Tortoise,
* probes to determine availability,
* and country managers to allow them to alter their country entry.
On request other end users may be granted access, if this is necessary.

What will change for -COUNTRY_ DSAs? (A country DSA masters the country 
entry)
Only known country DSAs will be allowed to connect via DSP (Directory
Systems Protocol) to the Giant Tortoise.
* Country DSAs should hold a copy of the root EDB for further dist
ribution
to other DSAs within that country.

What will change for all _OTHER_ DSAs? (non country DSAs)
In principle all other DSAs should connect to their country DSA.
To allow an easy transition the following DSAs will be allowed to 
connect:
* All DSAs that currently use the Giant Tortoise as a relay DSA.
* All DSAs that currently use the Giant Tortoise for replication.
These DSAs will be advised to use their country DSA during the coming 
period.

Every non-country DSA that has the quiputailor "parent" option set to 
Giant
Tortoise is suggested to replace "Giant Tortoise" with the name of their
country DSA (or other superior DSA).
For instance for @c=GB@cn=Urutu Snake quiputailor
was:    parent "cn= Giant Tortoise"     Internet=128.86.8.55 etc.
is:     parent "cn= Inca Dove"          Internet=128.86.8.65 etc.

The non-country DSAs should also replicate the root entry (EDB) from 
their
country DSA (or other superior DSA).

If there are any questions, please contact 
<helpdesk@nameflow.dante.net>.

So remember, testing will start on 2 May 1995 and full access 
restriction
will be effective as from 15 May 1995.

Regards,
        Vinc&

_____________________________________________________________________
            * *           Vincent Berkhout   -   Application Engineer
          *    *
        *                 Lockton House, Clarendon Road
       *                  Cambridge CB2 2BH, United Kingdom

    D  A  N  T  E         Tel. +44 1223 302992   Fax. +44 1223 303005
_____________________________________________________________________